The repository has tests, documentation, and dependency scanning, but no security policy. All 13 workflow actions are unpinned, and the audit missed one file.
45%
Total Score
50
100
72
50
The package is about 3 years and 11 months old, with no releases in the last 12 months and only 18 releases overall. That strongly lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, a strong indicator that development has stalled.
The release declares LGPL-3.0 and includes multiple license files, but the artifact also contains GPL-3.0 text not covered by the declaration, creating a licensing ambiguity.
The package and repository are owned by the same individual account rather than an organization, so there is no demonstrated organizational backing to offset the lack of recent activity.
There were no new or closed issues or pull requests in the last month, and one pull request remains open. This is consistent with limited current project activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laminas/laminas-escaper Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.